The worm inserts an UPX packed executable file in the user's directory and opens it.
This is a DLL 176,128 Bytes file with a random name and .TMP extension.
This file infects EXPLORER.EXE program, thus the virus being saved in memory.

Technical Details

W32/Partie.B attaches PE EXE and SCR files in Windows directory and in its subdirectories. It does not keep its original size.

The worm makes the following registry entry: HKEY_CURRENT_USER\Software\Microsoft\Windows\ CurrentVersion\Explorer\PINF
Some applications can not be restored after affected by the virus.